Jump to content

Autentikasi dua-faktor wajib bagi pengguna dengan hak akses tambahan tertentu

From Meta, a Wikimedia project coordination wiki
This page is a translated version of the page Mandatory two-factor authentication for users with some extended rights and the translation is 23% complete.
Outdated translations are marked like this.
As of December 2025, 2FA is available to all registered users on Wikimedia projects. See the help page.

Compared to other internet platforms, an exceptionally high number of Wikimedia users are able to take security- or privacy-sensitive actions. While these are generally trusted and competent members of the community, anyone can be phished or have their passwords stolen. If an account with such rights is taken over, it could be misused to hurt other users.

This is why the Wikimedia Foundation is shifting to a more secure system by requiring two-factor authentication (2FA) to log into accounts with sensitive permissions.

We have built a range of new features to make this easier: most importantly, users can now set up as many two-factor methods as they want, including passkeys. Once a user registers a passkey, they can then log in without using a password at all. For some users, passkeys will make logging in a quicker experience than it was for them before enabling two-factor authentication!

What are sensitive permissions?

When determining what user groups to include, the Wikimedia Foundation Product Safety and Integrity team considered any that had the ability to:

  • View private or confidential information (e.g., IP addresses, oversighted content)
  • Edit JS/CSS for other users (or for everyone)
  • Escalate permissions / promote users (add people to groups, including themselves)
  • And groups that implied an official role.

Technical enforcement of 2FA and automatic removal of permissions

Users who hold sensitive permissions but don't have 2FA enabled will be contacted directly before the enforcement date with instructions on how to enable 2FA. They should visit the special page and configure an authenticator app or a security key. After that, we encourage them to also add a passkey, which greatly simplifies login and reauthentication (see the guide).

Enforcement begins with a 2-week-long grace period. During this time, it is impossible to grant sensitive permissions to users who do not have 2FA enabled. In addition, the software does not allow users with sensitive permissions to disable 2FA. If a user wishes to temporarily disable 2FA during this time, they need to request removal of the sensitive permissions first, or self-remove, if they are able. They should coordinate with Stewards on the process of disabling and enabling 2FA again.

After this period, users who don't have 2FA enabled will automatically have their sensitive permissions removed. These users may re-apply for permissions through ordinary community processes.

Permissions that require two-factor authentication

Local groups

Local group Explanation Enforcement date
Pengurus pemberitahuan pusat Edit JS/CSS for other users Maret 2026
Pemeriksa Access to private or confidential information Maret 2026
Pengurus antarmuka Edit JS/CSS for other users Maret 2026
Pengawas Access to private or confidential information Maret 2026
Staf Wikidata Official role Maret 2026
Staf Wikifungsi Official role Maret 2026
Layanan TI WMF Official role Maret 2026
Kepercayaan dan Keamanan WMF Official role Maret 2026
Editors on foundationwiki Official role April 2026
Pengurus OAuth Access to private or confidential information April 2026
Penatalayan[1] Access to private or confidential information April 2026
Translation administrators on foundationwiki Official role April 2026
Anggota panitia arbitrase Access to private or confidential information Mei 2026
Birokrat Escalate permissions Mei 2026/Juni 2026

Global groups

Global group Explanation Enforcement date
Penolong filter penyalahgunaan Access to private or confidential information Juni 2026
Pemelihara filter penyalahgunaan Access to private or confidential information Juni 2026
Founder Official role Juni 2026
Penyunting antarmuka global Edit JS/CSS for other users Juni 2026
Pengurus global Edit JS/CSS for other users Juni 2026
importir wiki baru Access to private or confidential information Juni 2026
Ombudsman Access to private or confidential information Juni 2026
Staf Official role Juni 2026
Pengurus sistem Access to private or confidential information Juni 2026
Anggota U4C Access to private or confidential information Juni 2026
wmf-email-block-override Official role Juni 2026
Peneliti WMF Official role Juni 2026

Latar belakang

Beberapa minggu yang lalu, Wikimedia Foundation bekerja sama dengan fungsionaris komunitas untuk menyelidiki pelanggaran massal terhadap sekitar 36.000 akun pengguna. Salah satu langkah yang diambil dalam proses tersebut adalah mulai menerapkan secara teknis kewajiban autentikasi dua-faktor (2FA) bagi pengurus antarmuka wiki.

One of the steps we took as part of that work was to begin technically enforcing mandatory two-factor authentication for wiki interface administrators. We also expanded the technical enforcement of 2FA to oversighters and checkusers, given the privileged access they have to non-public information about editors.

In March of 2026, the Wikimedia Foundation made two-factor authentication technically mandatory for users for whom it was already required by policy. However, there are many other sensitive permissions that do not have this security protection in place. To help keep our projects and users safe, we have decided to expand our technical enforcement of 2FA to all user groups that take these actions.

Hubungi kami

Pemberitahuan ini disampaikan sebagai peringatan awal sebelum perubahan diberlakukan, sekaligus sebagai kesempatan untuk mengumpulkan masukan dari anggota komunitas. Kami menyambut segala pendapat mengenai cara terbaik untuk menerapkan kebijakan autentikasi dua-faktor seperti ini, baik saat ini maupun di masa mendatang. Kami juga terbuka terhadap saran mengenai peningkatan teknis pada fitur 2FA dan fitur terkait lainnya agar pengalaman ini menjadi lebih lancar bagi semua pihak.

Silakan kirim komentar Anda di halaman pembicaraannya. Jika Anda memiliki masukan pribadi, dapat dikirimkan melalui surel ke security-help(_AT_)wikimedia.org. Kami secara khusus tertarik untuk mengetahui:

  • Masalah apa yang pernah Anda alami, atau Anda lihat dialami oleh pengguna lain, mengenai autentikasi dua-faktor di proyek Wikimedia? Mohon sebutkan jika ada kekutu perangkat lunak, kekhawatiran keamanan, kurangnya dokumentasi, kesulitan kompatibilitas perangkat, atau hal lainnya.
  • Apakah ada persyaratan teknis lain selain 2FA yang sebaiknya dipertimbangkan sebagai syarat untuk mempertahankan akses istimewa di wiki?
  • Kelompok pengguna atau hak akses mana lagi yang sebaiknya menjadi fokus saat kami memperkuat kebijakan keamanan?
  • Hal apa yang paling perlu kami waspadai dalam menjalankan pekerjaan ini?
  • Komentar atau pertanyaan lain yang ingin Anda sampaikan.

Soal sering ditanya

References

  1. Technically, there are both global and local steward groups, and the latter are only available to the members of the former. 2FA will be enforced on the local level first. Because of this, there will be no practical consequences of the global enforcement (set to happen later), as all stewards will have 2FA enforced by then.

Lihat pula